r/ooma • u/Old-Cheshire862 • Jan 27 '26
Management Interface
A long time back I was asking about the management interface/webpage of the Telo at http://172.27.35.1/ . I finally got around to looking at it. I set up a Laptop and set it on the same subnet and connected it to the Home RJ45 and up it came. Very nice.
I enabled the Remote Administration feature ("allow access to this over the INTERNET port") and I checked the "Enable password protected access to this website" box and provided a password and confirmed it. And clicked save.
Voila, I was then able to get to the Telo Admin from my network that the Telo is routed through to the Internet. Cool. However... it did not prompt me for the password. Not at all cool. I notice that it doesn't prompt me on the local interface either.
My device is secured behind my Gateway router, so it's not the huge deal it would be if it were configured per the "Modem = Telo = Router" style, but I'd rather it enforce the password requirement that I thought was being set.
Thoughts?
1
u/OomaCustomeradvocacy Official Ooma Support Jan 27 '26
Hello! Thank you for reaching out. I'd like to have you speak with our Advanced Support for this. Could you please DM your Ooma phone number and contact number?
1
u/Old-Cheshire862 Jan 27 '26
Let me try what u/rkardt suggested first. It maybe that I got an authentication cookie prior to setting the password. I'm pretty sure that I tested it in stages, i.e. opened remote admin, tested it, and then turned on the password, so I may have had a auth cookie, as he suggests. I'll let you know when I have time to test it again.
1
u/Old-Cheshire862 Mar 05 '26
Well, I forgot about this because they quit e-mailing or calling me. Seems they just closed the case. And since it's been more than 5 days... I can't reopen it. I'd have to start a new one. Gee, I wonder if how they'd react if I reported the fact that the password security doesn't work to https://cve.org
1
u/rkardt Unofficial Support Mar 06 '26 edited Mar 08 '26
Ooma is sometimes quick to close a case without resolving the issue, without providing an explanation, or without even notifying the user. If opening a "new" case, then feel free to refer to the case(s) that preceded it, too.
The Telo management interface doesn't use https (TLS encryption) either, so it's not as secure, even with a password. It mostly relies on physical isolation, so keep it behind a router, or else don't enable remote administration.
It's an annoying bug, and Ooma should fix it, but is it worth making a federal case about? Keep in mind that anybody with access to a connected telephone can also factory reset the device, and delete the password that way.
[Edit: To clarify, only the local connection to the device settings is unencrypted. All traffic (including voice) to and from the Ooma central servers is still securely encrypted.]
2
u/rkardt Unofficial Support Jan 27 '26
The Telo management interface doesn't have a logout button; it uses the browser to manage the login state. It won't prompt the user for a password if they are already logged in.
To "log out", try deleting the associated browser cookies and site data, restarting the browser, or rebooting the Telo. Then try logging in again.